Security Certifications

ISO/IEC 27001 is an international standard for information security management published by the International Organization for Standardization. It defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) — a structured framework of policies, processes, and controls for managing information security risk.

Key components include:

  • Context — understanding the organization, its stakeholders, and the scope of the ISMS
  • Leadership — commitment from management and defined roles and responsibilities
  • Planning — identifying risks and opportunities, setting security objectives, and planning to achieve them
  • Support — ensuring adequate resources, competence, awareness, and documented information
  • Operation — implementing and controlling processes to meet ISMS requirements
  • Performance evaluation — monitoring, measurement, analysis, and evaluation of the ISMS
  • Improvement — continual improvement of the ISMS based on evaluation results

ISO 27001 certification is awarded following an audit by an accredited certification body. Certification requires periodic surveillance audits and recertification to remain current. Accreditation bodies include ANAB (anab.ansi.org) and the ISO directly (iso.org).

What is SOC 2 Type 2 Certification?

SOC 2 (System and Organization Controls 2) is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA) that defines how service providers should manage and protect client data. A SOC 2 Type 2 certification is issued following an independent audit conducted by a licensed CPA firm, covering an extended period — typically six to twelve months — rather than a single point in time.

The audit evaluates controls across five trust service criteria:

  • Security — the system is protected against unauthorized access
  • Availability — the system is available for operation and use as committed
  • Processing Integrity — system processing is complete, valid, accurate, timely, and authorized
  • Confidentiality — information designated as confidential is protected as committed
  • Privacy — personal information is collected, used, retained, and disposed of in conformity with the provider’s stated privacy commitments

The AICPA sets the standards for SOC 2. Licensed CPA firms accredited by the AICPA conduct the audits. A current SOC 2 Type 2 report documents the results of that audit for the covered period.

Dealerships handle sensitive data across multiple departments — customer personally identifiable information, credit applications, service history, financing records, and data connected to dealer management systems. When a software or service provider has access to any of that data, the dealer has an interest in understanding how that provider manages and protects it.

SOC 2 Type 2 and ISO 27001 are two of the most widely recognized independent frameworks for verifying that a vendor has documented security controls in place. Both involve third-party audits conducted against established standards rather than self-assessment. The primary distinctions are:

  • SOC 2 Type 2 is specific to the United States, governed by the AICPA, and evaluates controls over a defined time period
  • ISO 27001 is an international standard applicable across jurisdictions and evaluates the overall information security management system

Neither framework is universally required for dealership software vendors. Dealers evaluating vendors with access to customer data, DMS feeds, or financial systems may request a current SOC 2 Type 2 report or ISO 27001 certificate as part of their vendor evaluation process.

Dealer Software Success tracks MCP readiness across software and service providers in our AI Provider Rankings as this information becomes available.

If you would like something added to our FAQs page, please use the Contact Us link at the bottom of this page.